CVE Database
/

CVE-2015-8778

Back to search

CVE-2015-8778

Published: Apr 19, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.

VendorProductVersions

n/a

n/a

affected
n/a

References

SUSE-SU-2016:0471
vendor-advisory
x_refsource_SUSE
FEDORA-2016-68abc0be35
vendor-advisory
x_refsource_FEDORA
RHSA-2017:1916
vendor-advisory
x_refsource_REDHAT
DSA-3481
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2016:0510
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:0470
vendor-advisory
x_refsource_SUSE
RHSA-2017:0680
vendor-advisory
x_refsource_REDHAT
USN-2985-2
vendor-advisory
x_refsource_UBUNTU
GLSA-201702-11
vendor-advisory
x_refsource_GENTOO
GLSA-201602-02
vendor-advisory
x_refsource_GENTOO
SUSE-SU-2016:0472
vendor-advisory
x_refsource_SUSE
SUSE-SU-2016:0473
vendor-advisory
x_refsource_SUSE
DSA-3480
vendor-advisory
x_refsource_DEBIAN
USN-2985-1
vendor-advisory
x_refsource_UBUNTU
83275
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now